7.3
CVSSv3

CVE-2015-6831

Published: 19/01/2016 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 7.3 | Impact Score: 3.4 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple use-after-free vulnerabilities in SPL in PHP prior to 5.4.44, 5.5.x prior to 5.5.28, and 5.6.x prior to 5.6.12 allow remote malicious users to execute arbitrary code via vectors involving (1) ArrayObject, (2) SplObjectStorage, and (3) SplDoublyLinkedList, which are mishandled during unserialization.

Vulnerable Product Search on Vulmon Subscribe to Product

php php

debian debian linux 8.0

debian debian linux 7.0

Vendor Advisories

Several security issues were fixed in PHP ...
Multiple vulnerabilities have been discovered in the PHP language: CVE-2015-4598 thoger at redhat dot com discovered that paths containing a NUL character were improperly handled, thus allowing an attacker to manipulate unexpected files on the server CVE-2015-4643 Max Spelsberg discovered an integer overflow flaw leading to a ...
A flaw was discovered in the way PHP performed object unserialization Specially crafted input processed by the unserialize() function could cause a PHP application to crash or, possibly, execute arbitrary code ...
PHP process crashes when processing an invalid file with the "phar" extension (CVE-2015-5589) As discussed <a href="bugsphpnet/bugphp?id=69669">upstream</a>, mysqlnd is vulnerable to the attack described in <a href="wwwduosecuritycom/blog/backronym-mysql-vulnerability">wwwduosecuritycom/blog/backron ...
PHP process crashes when processing an invalid file with the "phar" extension (CVE-2015-5589) As discussed <a href="bugsphpnet/bugphp?id=69669">upstream</a>, mysqlnd is vulnerable to the attack described in <a href="wwwduosecuritycom/blog/backronym-mysql-vulnerability">wwwduosecuritycom/blog/backron ...
PHP process crashes when processing an invalid file with the "phar" extension (CVE-2015-5589) As discussed <a href="bugsphpnet/bugphp?id=69669">upstream</a>, mysqlnd is vulnerable to the attack described in <a href="wwwduosecuritycom/blog/backronym-mysql-vulnerability">wwwduosecuritycom/blog/backron ...